Bug 34182 - poppler new security issues CVE-2025-3236[45]
Summary: poppler new security issues CVE-2025-3236[45]
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-04-09 15:25 CEST by Nicolas Salguero
Modified: 2025-04-12 06:24 CEST (History)
3 users (show)

See Also:
Source RPM: poppler-23.02.0-1.4.mga9.src.rpm
CVE: CVE-2025-32364, CVE-2025-32365
Status comment:


Attachments

Description Nicolas Salguero 2025-04-09 15:25:16 CEST
Ubuntu has issued an advisory on April 8:
https://ubuntu.com/security/notices/USN-7426-1
Nicolas Salguero 2025-04-09 15:26:06 CEST

Source RPM: (none) => poppler-25.01.0-1.mga10.src.rpm, poppler-23.02.0-1.4.mga9.src.rpm
Status comment: (none) => Fixed upstream in 25.04.0 and patch available from Ubuntu
Whiteboard: (none) => MGA9TOO
CVE: (none) => CVE-2025-32364, CVE-2025-32365

Comment 1 Nicolas Salguero 2025-04-09 15:27:50 CEST
openSUSE has issued an advisory on April 8:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/7MHRTVNCUQHLCEUDCYX24NK4ID3BMFG5/

Status comment: Fixed upstream in 25.04.0 and patch available from Ubuntu => Fixed upstream in 25.04.0 and patch available from Ubuntu and openSUSE

Nicolas Salguero 2025-04-09 15:28:01 CEST

Status comment: Fixed upstream in 25.04.0 and patch available from Ubuntu and openSUSE => Fixed upstream in 25.04.0 and patches available from Ubuntu and openSUSE

Comment 2 Lewis Smith 2025-04-09 21:06:47 CEST
I think these are the patches for the 2 CVEs:

https://gitlab.freedesktop.org/poppler/poppler/-/commit/1f151565bbca5be7449ba8eea6833051cc1baa41

https://gitlab.freedesktop.org/poppler/poppler/-/commit/d87bc726c7cc98f8c26b60ece5f20236e9de1bc3

Although assigning globally, ns80 might do this (already CC'd as bug creator).

Assignee: bugsquad => pkg-bugs

Comment 3 Nicolas Salguero 2025-04-11 10:54:48 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerabilities:

A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN. (CVE-2025-32364)

Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check. (CVE-2025-32365)

References:
https://ubuntu.com/security/notices/USN-7426-1
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/7MHRTVNCUQHLCEUDCYX24NK4ID3BMFG5/
========================

Updated packages in core/updates_testing:
========================
lib(64)poppler-cpp-devel-23.02.0-1.5.mga9
lib(64)poppler-cpp0-23.02.0-1.5.mga9
lib(64)poppler-devel-23.02.0-1.5.mga9
lib(64)poppler-gir0.18-23.02.0-1.5.mga9
lib(64)poppler-glib-devel-23.02.0-1.5.mga9
lib(64)poppler-glib8-23.02.0-1.5.mga9
lib(64)poppler-qt5-devel-23.02.0-1.5.mga9
lib(64)poppler-qt5_1-23.02.0-1.5.mga9
lib(64)poppler-qt6-devel-23.02.0-1.5.mga9
lib(64)poppler-qt6_3-23.02.0-1.5.mga9
lib(64)poppler126-23.02.0-1.5.mga9
poppler-23.02.0-1.5.mga9

from SRPM:
poppler-23.02.0-1.5.mga9.src.rpm

Version: Cauldron => 9
Status comment: Fixed upstream in 25.04.0 and patches available from Ubuntu and openSUSE => (none)
Whiteboard: MGA9TOO => (none)
Assignee: pkg-bugs => qa-bugs
Source RPM: poppler-25.01.0-1.mga10.src.rpm, poppler-23.02.0-1.4.mga9.src.rpm => poppler-23.02.0-1.4.mga9.src.rpm
Status: NEW => ASSIGNED

Comment 4 Herman Viaene 2025-04-11 15:29:51 CEST
MGA9-64 Plasma wayland on Compaq H000SB
No installation issues.
Tests from bug 32242:
$ pdftohtml handleidingVM.pdf testpoppler.html
Page-1
Page-2
Page-3
Page-4
Page-5
Page-6
Page-7
Page-8
Page-9
 link to page 6 Page-10
Page-11
Page-12

$ firefox testpoppler.html
Opens correctly with a page index as a lefthand column of links and the text and graphics to the right.
$  pdftotext handleidingVM.pdf VM.txt
Opened with mousepad and text is complete with indicators where graphical items occured in the original document. These indicators are not shown in kate.
From bug 32600
$ pdfimages handleidingVM.pdf handvm
[tester9@mach3 testpoppler]$ ls handvm*
handvm-000.ppm  handvm-001.ppm  handvm-002.ppm  handvm-003.ppm  handvm-004.ppm  handvm-005.ppm  handvm-006.ppm  handvm-007.ppm
$ ls ha*.ppm | wc -l
8
$ pdfseparate -f 3 -l 10 handleidingVM.pdf page_%d
$ okular page_*
pages show up OK.
Should be good enough.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA9-64-OK

Comment 5 Thomas Andrews 2025-04-12 01:22:41 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

katnatek 2025-04-12 03:33:58 CEST

Keywords: (none) => advisory

Comment 6 Mageia Robot 2025-04-12 06:24:54 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0134.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.